sreroot

Runbooks / High CPU

\n

High CPU

\n

Kubernetes · Java · incident notes

\n
\n

Purpose

\n

Investigate and mitigate sustained or sudden CPU utilization in Java services running on Kubernetes.

\n

Symptoms

\n\n

Initial Triage

\n
kubectl top pods -n <namespace> --sort-by=cpu\nkubectl top nodes\nkubectl get hpa -n <namespace>\nkubectl describe pod <pod> -n <namespace>\nkubectl get events -n <namespace> --sort-by=.lastTimestamp
\n

Check the configured requests and limits:

\n
kubectl get deploy <deployment> -n <namespace> -o yaml
\n

Look for:

\n\n

JVM and Thread Investigation

\n

Identify the Java process:

\n
kubectl exec -n <namespace> <pod> -- sh -c 'ps -ef | grep java'
\n

Capture thread CPU usage:

\n
kubectl exec -n <namespace> <pod> -- top -H -p <java-pid>
\n

Convert a hot Linux thread ID to hexadecimal:

\n
printf '%x\n' <thread-id>
\n

Capture a thread dump:

\n
kubectl exec -n <namespace> <pod> -- jcmd <java-pid> Thread.print
\n

Correlate the hexadecimal thread ID with the \1 value in the thread dump.

\n

Java Flight Recorder

\n

Start a short diagnostic recording where permitted:

\n
kubectl exec -n <namespace> <pod> --   jcmd <java-pid> JFR.start name=cpu-investigation duration=120s filename=/tmp/cpu.jfr settings=profile
\n

Copy the recording:

\n
kubectl cp <namespace>/<pod>:/tmp/cpu.jfr ./cpu.jfr
\n

Review:

\n\n

Common Causes

\n\n

Mitigation

\n\n

Validation

\n
kubectl top pods -n <namespace>\nkubectl get hpa -n <namespace>
\n

Confirm:

\n\n

Evidence to Capture

\n\n